Industrial network responses to cyber attack risks for preventive measures

  Recently, the largest fuel transportation pipelines in the United States have been suspended from cyber security, leading to the state to announce in an emergency, causing safety industry hot discussion. As OT technology is constantly incorporated with information technology (IT), the use of IT technology is increasingly becoming an attack OT system and generating a destructive hub, how to protect industrial Internet networks, prevent attackers from successfully executing control commands and generate destructiveness Network impact?


Earlier, the US National Security Agency (NSA) released an announcement of industrial network security risk response recommendations, pointing out the security threats in key infrastructure, and provided suggestions on how to protect the industrial control system. This paper translates and references the main content of the announcement, and the management of the management of industrial networks and OT systems, enhances the monitoring and detection capabilities of OT network environment, and prevents the catastrophic impact of network intrusion.

Measures to improve network security


From the corporate leadership to OT system operators, many people are asking: "Under limited resources, how can we improve the network security of OT and control systems and ensure success?" In order to answer this question, NSA proposes the practical use of OT networks. Assessment methods and basic network security improvement methods.


Comprehensively assess the value, risk and cost of enterprise IT-to-OT connection


(1) Recognizing that the independent, unconnected island type OT system is more secure than connecting to an external connection to a system of enterprise IT systems (regardless of external connection is considered to be as secure). Intermittently connected OT systems may be a good compromise because it only has risks when they are connected, only when needed, such as downloading updates or time required to be remotely accessed within a limited time.


(2) Connect the IT system to the OT network and / or control the system environment to valuable business, involving many aspects, including:


Easy to connect and use data / information.

Take advantage of existing capabilities such as TT technicians.

System monitoring is performed using or combined with IT tools.

Implement theoretical synergies through IT integration, such as management of OT assets.

(3) Connect the IT system to the risk of the OT environment to enterprises, may involve aspects, including:


  hard to control.

Security system / equipment cannot work properly.

Revenue loss caused by interrupt or closing.

If the security system / equipment is not operating abnormal, people will cause casualties when they are serious.

(4) Quantifier due to the additional cost of connecting existing OT networks and equipment to enterprise IT systems, the cost may involve many aspects, including:


Segmentation and protection of OT networks and infrastructure to reduce the risk of large-scale hazards.

Download and update the update product or system license fee required for OT assets to the latest version. This is critical to mitigating potential vulnerabilities with respect to outdated firmware, software, etc., and is also necessary for reducing the risk used in connection environments.

If the OT asset contains the service life that is about to expire or is about to provide product support, the upgrade cost of the OT system will increase. This should not only include equipment costs, but also any potential income loss or task availability due to replacement and testing of OT device.

Additional personnel and resources are required to properly maintain and protect OT assets.

(5) Provide report results to the leaders so they can effectively assess value, risk and cost / resources.


Improve network security connecting to enterprises IT-to-OT network


Strategy, existing IT resources and freely available tools should be more secure to enterprise IT-To-OT networks, which also apply to network and system of intermittent connection to improve network recovery capabilities and ensure task preparation. Ready.


(1) Comprehensive management, encryption protection (encryption, and authentication), and set a list of access to access channels to ensure that all access attempts are recorded. Access channels can include many aspects, for example:


Suppliers or any outsourcing IT asset support, including supplier portable computers with known and unknown remote monitoring.

Remote connections for monitoring and / or alert notification.

Internal access, especially through existing open, non-managed networks, servers, or equipment.

Direct physical access.


(2) Add monitor probes and monitor all cross-domain connections anywhere to allow remote access. It is recommended to disconnect all remote access until proactive monitoring.


(3) Creating an OT web map and device setting baseline and verifying all devices on the network.


Use terrain and physical network drawing and inventory.


Use existing open source tools that meet the requirements.


(4) Creating OT network communication benchmarks


Use existing open source tools that meet the requirements.


(5) Assess the network security needs of the OT network and determine its priority to identify the desired mitigation measures and define short-term, medium and long-term network security improvements.


Develop a valid network security improvement plan according to internal IT / OT expertise, and give priority to specific OT network security risks. It will also provide a roadmap for continuous application of mitigation measures, recent policies to improve and implement long-term network security objectives.


(6) Create a backup baseline to make all OT networks and devices to fix and rebuild.


The key backup file should keep a copy of the area where the unconnected position is not connected, and the area that cannot be accessed online.


When there is a security issue or malicious attack, reopen the OT network, take steps to ensure success to shorten the downtime of the OT network.


Although there is a very realistic requirement for network connection and automation, the OT network and control system are connected to the enterprise IT system itself is risky. Before connecting (or keeping a connection) Enterprise IT network, we must carefully evaluate risks, benefits and costs.


Before allowing enterprise IT-to-OT connections, cautiously, priority and considering risks. Although the OT system is rarely required to work properly, it is often connected to the convenience, and they are often connected without properly considering real risks and potential disadvantages. It is recommended to follow the above methods to take immediate action to help them increase network security.


  Thermal solutions for every industry is very important as the power is gradually higher and higher, Sinda Thermal can provide varieties heatsinks and coolers which inlcuding aluminum extruded heatsink, high performance heatsink, copper heatsink, skived fin heatsink, and heat pipe heatsink. please contact us if you have any questions about thermal solution.

website: www.sindathermal.com

contact:castio_ou@sindathermal.com

Wechat: +8618813908426


You Might Also Like

Send Inquiry